Privacy policy
Shinun / שינון · com.benbasha.shinun · last updated 20 September 2026
In short: no account, no sign-up. Your decks and cards are stored on your device. There are no ads and no cross-app tracking. Anonymous, aggregated usage and crash data help fix bugs and improve the app. The one time your content leaves the device is when you tap Share on a deck. That uploads a read-only copy so the person you send the link to can open it.
What the app is
Shinun is an offline flashcard app with spaced repetition (FSRS). You create or import decks, study them in several modes, and the scheduler decides what you see next. There are no user accounts, no social feed, no ads, and no server that holds your study data.
Data that stays on your device
Stored locally and never uploaded to us:
- your decks and cards (both faces, any extra note, tags);
- your review history and scheduling state (FSRS parameters, due dates, lapses);
- your study sessions (start/end time, mode, counts);
- your settings: theme, language, study preferences, TTS on/off, the premium entitlement flag, and local kill switches;
- the home-screen / Lock-Screen widget snapshot, which is written to an App Group container on the same device.
Uninstalling the app deletes all of it. There is no cloud copy for us to restore, and no “sign in on a new phone” path.
For completeness: the local database and the preference store are not encrypted at rest by the app. The device’s own disk encryption is what protects them.
Sharing a deck (the only content upload, and only if you ask for it)
When, and only when, you tap Share on a deck, the app uploads a read-only snapshot of that deck to Google Firebase (Cloud Firestore) and gives you a link: https://shinun.benbasha.com/d/<id>.
- What is uploaded: the deck’s name, its two language/direction settings, and its cards (front, back, optional extra note), plus a card count, a timestamp, and the app version. Nothing else. There is no name, no email, no device identifier and no user id inside the document.
- Why it is authenticated anonymously: the write requires Firebase Anonymous Authentication. That is a rate-limiting and abuse-protection handle, not an identity: it lets Firebase see “a caller” so the rules can refuse floods. The anonymous id is generated on the device, is not tied to you, and is not stored inside the shared document.
- Who can read it: anyone who has the link. The id is 10 random base62 characters (~59 bits), and the security rules allow fetching a document by id only. The collection cannot be listed, so there is no way to browse other people’s shares.
- It cannot be edited or deleted from the app. A snapshot is a photograph: by design the rules deny updates and deletes, so what you sent stays what you sent, and edits you make afterwards stay with you. If you need a snapshot removed, email shinun@benbasha.com with the link.
- Receiving a link downloads the snapshot and previews it; nothing enters your library until you accept, and what you then get is your own local copy.
- Do not share decks containing information you would not put on a public web page. A link is the only protection, and links get forwarded.
- Size limits (2,000 cards, 200 KB) are enforced both in the app and in the security rules; oversized decks are exported as a file instead.
Anonymous usage and crash data
To understand which features are used and to fix crashes, the app sends anonymous, aggregated events to Mixpanel and to Google Firebase (Google Analytics for Firebase + Crashlytics). These providers process the data on our behalf; we do not sell it and we do not share it for anyone else’s purposes.
What these events carry (this list is the allowlist the code enforces):
- counts and durations: how many cards were in a session, how long it took, how many cards an import produced;
- kinds and modes: which study mode, which import source, which paywall trigger, which failure reason code;
- app state: app version, OS version, device model, interface language;
- a random, app-scoped installation identifier generated by the analytics SDKs (Firebase’s app-instance id, Mixpanel’s distinct id). It is not the advertising id, it is not shared with anyone, and it is reset when you reinstall.
What they never carry: card text, deck names, imported file contents, typed answers, file names, or any free text you wrote. Import failures report a reason code, never a line of your file. This is enforced by sanitize() in the app’s analytics layer, not merely by convention.
There is no advertising identifier: the Android build strips the AD_ID permissions, there is no App Tracking Transparency prompt because the app never tracks, and no ad SDK is present.
Purchases
Shinun is free with one optional, one-time purchase (shinun_premium) that unlocks the paid features. Payment is handled entirely by Apple and Google; we never see your card, your billing address or your Apple/Google account. The app stores only a local flag saying the purchase is active. Note that Google Analytics for Firebase automatically records an in-app-purchase event for store transactions, so purchase history is listed in our store data declarations even though our own code does not send it.
What the app does NOT collect
No name, email address, phone number or postal address. No precise location: the app has no location permission and no GPS access. Google Analytics for Firebase derives an approximate, city-level location from your IP address (the IP is masked and not stored); Mixpanel’s IP geolocation is turned off. No contacts, calendar, photos, microphone or camera access. No health data. No browsing or search history. No advertising identifier. No cross-app or cross-site tracking of any kind.
Children
Shinun is a general-audience study app, not directed at children. On Google Play its target age group is 13 and over. It is not a Families-programme app and contains no child-directed content.
Your choices and your rights
- Stop all local storage: delete the app; everything local goes with it.
- Stop analytics: the app has no in-app analytics toggle today. You can use your OS-level controls (iOS: Settings → Privacy & Security → Analytics & Improvements / “Allow Apps to Request to Track”, which Shinun never asks for; Android: Settings → Google → Ads). If you want your anonymous analytics records purged, email shinun@benbasha.com and say so.
- Remove a shared deck: email shinun@benbasha.com with the link.
- Access / deletion requests (GDPR, CCPA and similar): email shinun@benbasha.com. Because there is no account, we usually cannot find “your” data without something to match on (a share link, an approximate time), and in most cases there is nothing of yours on our side at all.
Data deletion
There is no account to delete. Uninstalling the app deletes every piece of study data, because all of it lives on the device. The only data that can exist off the device is a deck snapshot you chose to share; email shinun@benbasha.com with the link and it will be removed. Analytics records are anonymous and aggregated and are retained by the providers under their own retention schedules (Firebase: up to 14 months for event data; Mixpanel: the project’s retention window).
Sub-processors
| Provider | What it processes | Where |
|---|---|---|
| Google Firebase (Analytics, Crashlytics) | anonymous usage + crash events | Google Cloud (US) |
| Google Cloud Firestore | deck snapshots you chose to share | Google Cloud (US, nam5) |
| Mixpanel | anonymous usage events | US data residency |
| Apple / Google | purchase processing | their own terms |
Changes
If this policy changes materially, the app’s store listing and this page are updated and the date at the top changes.